CVE-2026-14231: Unknown Lifterlms

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.

Affected products

  • Unknown Lifterlms: before 10.0.10 (fixed in 10.0.10)

Published 2026-07-30. Last modified 2026-07-30.